A flaw in Meta's AI support chatbot let attackers take over more than 20,000 Instagram accounts. Two-factor authentication was no defense.
Meta disclosed the breach in a regulatory notice filed with the state of Maine. The attack required no sophistication: an attacker could ask the chatbot for a password reset while supplying an email address that didn't belong to the target account. A bug in what Meta calls a "separate code path" meant the system skipped the step that checks whether the provided email matches the one on file. At least 20,225 accounts were compromised before the flaw was addressed.
Folding AI assistants into account recovery flows is a relatively recent practice, and this incident shows the cost of moving fast there. The conversational interface can make these flows feel more trustworthy to users, even as it introduces attack surfaces that traditional web forms didn't have. That 2FA offered zero protection means even security-conscious users were fully exposed.
Meta's framing is worth reading carefully: the company says the chatbot "functioned as intended" and pins the failure on a separate piece of code. Technically accurate. Also a tidy way to keep the AI product at arm's length from a breach affecting tens of thousands of people.
